Received: by 2002:a25:1985:0:0:0:0:0 with SMTP id 127csp685304ybz; Fri, 1 May 2020 06:47:42 -0700 (PDT) X-Google-Smtp-Source: APiQypLSp/n8MS2jTqGddxqPiwyrr2JRwhsQlQLL2XPi0tNV8U+lqm2GVrIpgUz0GLweMeej8SzJ X-Received: by 2002:aa7:d3cb:: with SMTP id o11mr3456424edr.194.1588340861909; Fri, 01 May 2020 06:47:41 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1588340861; cv=none; d=google.com; s=arc-20160816; b=ZeJ2rHv7Su59sB6V0NRxcFNfD8/uDQ7n2g9rmOyUTXTHVOcde/JlIQ21YEoy198RTR v/sPMLXO6oFVL4AHd8N7q3+AtlsW0bJT+uB0yJFLwDnlj1z16QpJGpY6hENPfV3BJL7I v4EcEj1PQ+TNjdSvbtAXrPzCXA3eVXXtt9KC/X5qj8JjMk2vgJAgwtRLU4pwUxeqNYaM RMIhlF31kOpNEMaotAeJ6hfAb9rblfcPc3J9SvVKWhJQN45ZgH2VZb22DvYxfBmk3mIl cI7Pghl0gJ94w/oAwB0kG7t8mKvB+K952hU6aGo1DjLDNJkXPLXRXKOVpElHaiaFXYwD Al5Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=B1dBZygdOuEOVVgRDxzrxsbu/gYOSkCw10Yi3BStOb4=; b=VNHqUDC+0XJTA3Rp9aPRLxTOov+SpfG7Aykyd1s+KLczmTnJ05Kbg2mWmdlddntMJO Jt5mTttHV/PTbwKiVmKeXbEfhKLqFnCTv/OMXBysS5o7iR2MdE08xSgZO6AHE4X9ZoGZ PCm0lXxfM7rzAHtSuII8g1ETor0sF/BR9OjMBlMN79HVqxiifO59YMzkbdnqZG9hYlDo GLXW6p2hDeRCxGvS0aPFFCOBBx3qS2RKZXPV4wsudcDK/87op9pPwke54yRAKw0Ww75n zCVWExK6wfStdOP3I/jn/YKfpOC0X0ptTQII8dN/IvCV+Ayi1paSRR6DYybGPlBXlO1E ++Kg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id t27si1693626edt.42.2020.05.01.06.47.19; Fri, 01 May 2020 06:47:41 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1731641AbgEANqD (ORCPT + 99 others); Fri, 1 May 2020 09:46:03 -0400 Received: from mail-lj1-f196.google.com ([209.85.208.196]:34617 "EHLO mail-lj1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731899AbgEANpQ (ORCPT ); Fri, 1 May 2020 09:45:16 -0400 Received: by mail-lj1-f196.google.com with SMTP id f11so2677317ljp.1; Fri, 01 May 2020 06:45:15 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=B1dBZygdOuEOVVgRDxzrxsbu/gYOSkCw10Yi3BStOb4=; b=nhF7S23Y/ZJo0T5XTS8G/hjloPB2T52myLZuRnIGr+uVidboPKqGYmLGRMYw3yTeX4 D8MbshqU3fKZEFG3qXOuFzZcMeUbZWkQkwOhYAnS8Y6YTjTkRhFTIH8LsNCLf+djiI3C rXHo3jiJvCVPkk6TXbHgjCiK+5ZjlfEYeB8oRNjXXr9mz0i4487FxLcneML0ZkvIEgsH fPdy9V/37jDYvFPEXQeU5NFxyFh4kLl7RXRDYfoo+y7FFGLSN0kmF9sWlWdx1hubjVwQ m1j9RQHkHND1WsPaaCJIxMJVBaUBMYNivSl4KfmChn26+9Zmim48dxkwkQXLm+/UOpPr rxvQ== X-Gm-Message-State: AGi0PubTuHdHGkr/U55JgAy0DSnQLP84qRm4AWyRSZ4pzttsw7sfYZuK uliy3LhSFmhf6s1cVJWA13X4Ars1zHg= X-Received: by 2002:a2e:731a:: with SMTP id o26mr2570638ljc.189.1588340714141; Fri, 01 May 2020 06:45:14 -0700 (PDT) Received: from localhost.localdomain ([213.87.150.177]) by smtp.googlemail.com with ESMTPSA id b2sm2269194lfi.14.2020.05.01.06.45.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 01 May 2020 06:45:13 -0700 (PDT) From: Denis Efremov To: linux-block@vger.kernel.org Cc: Denis Efremov , Willy Tarreau , Christoph Hellwig , Joe Perches , linux-kernel@vger.kernel.org, Christoph Hellwig Subject: [PATCH v3 4/4] floppy: suppress UBSAN warning in setup_rw_floppy() Date: Fri, 1 May 2020 16:44:16 +0300 Message-Id: <20200501134416.72248-5-efremov@linux.com> X-Mailer: git-send-email 2.25.3 In-Reply-To: <20200501134416.72248-1-efremov@linux.com> References: <20200501134416.72248-1-efremov@linux.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org UBSAN: array-index-out-of-bounds in drivers/block/floppy.c:1521:45 index 16 is out of range for type 'unsigned char [16]' Call Trace: ... setup_rw_floppy+0x5c3/0x7f0 floppy_ready+0x2be/0x13b0 process_one_work+0x2c1/0x5d0 worker_thread+0x56/0x5e0 kthread+0x122/0x170 ret_from_fork+0x35/0x40 From include/uapi/linux/fd.h: struct floppy_raw_cmd { ... unsigned char cmd_count; unsigned char cmd[16]; unsigned char reply_count; unsigned char reply[16]; ... } This out-of-bounds access is intentional. The command in struct floppy_raw_cmd may take up the space initially intended for the reply and the reply count. It is needed for long 82078 commands such as RESTORE, which takes 17 command bytes. Initial cmd size is not enough and since struct setup_rw_floppy is a part of uapi we check that cmd_count is in [0:16+1+16] in raw_cmd_copyin(). The patch adds union with original cmd,reply_count,reply fields and fullcmd field of equivalent size. The cmd accesses are turned to fullcmd where appropriate to suppress UBSAN warning. Reviewed-by: Christoph Hellwig Signed-off-by: Denis Efremov --- drivers/block/floppy.c | 4 ++-- include/uapi/linux/fd.h | 11 ++++++++--- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/drivers/block/floppy.c b/drivers/block/floppy.c index 9e098d53b046..064c1acb9f00 100644 --- a/drivers/block/floppy.c +++ b/drivers/block/floppy.c @@ -1070,7 +1070,7 @@ static void setup_DMA(void) if (raw_cmd->length == 0) { print_hex_dump(KERN_INFO, "zero dma transfer size: ", DUMP_PREFIX_NONE, 16, 1, - raw_cmd->cmd, raw_cmd->cmd_count, false); + raw_cmd->fullcmd, raw_cmd->cmd_count, false); cont->done(0); fdc_state[current_fdc].reset = 1; return; @@ -1515,7 +1515,7 @@ static void setup_rw_floppy(void) r = 0; for (i = 0; i < raw_cmd->cmd_count; i++) - r |= output_byte(current_fdc, raw_cmd->cmd[i]); + r |= output_byte(current_fdc, raw_cmd->fullcmd[i]); debugt(__func__, "rw_command"); diff --git a/include/uapi/linux/fd.h b/include/uapi/linux/fd.h index 2e9c2c1c18e6..8b80c63b971c 100644 --- a/include/uapi/linux/fd.h +++ b/include/uapi/linux/fd.h @@ -371,9 +371,14 @@ struct floppy_raw_cmd { */ unsigned char cmd_count; - unsigned char cmd[FD_RAW_CMD_SIZE]; - unsigned char reply_count; - unsigned char reply[FD_RAW_REPLY_SIZE]; + union { + struct { + unsigned char cmd[FD_RAW_CMD_SIZE]; + unsigned char reply_count; + unsigned char reply[FD_RAW_REPLY_SIZE]; + }; + unsigned char fullcmd[FD_RAW_CMD_FULLSIZE]; + }; int track; int resultcode; -- 2.25.3